vendor:
WebSite Builder PRO
by:
Dedi Dwianto a.k.a the_day
9
CVSS
CRITICAL
Remote File Inclusion
98
CWE
Product Name: WebSite Builder PRO
Affected Version From: 1.9.2008
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Company WebSite Builder PRO (INCLUDE_PATH) Remote File Inclusion Vulnerability
The vulnerability is caused by an invalid include function in the comanda.php file, which allows an attacker to include remote files and execute arbitrary code.
Mitigation:
Update to a patched version that fixes the remote file inclusion vulnerability.